Skip to content
View harekrishnarai's full-sized avatar
:octocat:
Securing apps via pentesting, code reviews & supply chain defense 🔐
:octocat:
Securing apps via pentesting, code reviews & supply chain defense 🔐

Block or report harekrishnarai

Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
harekrishnarai/README.md

Hey there, I'm Hare Krishna Rai

Twitter Badge    LinkedIn Badge

CRTP Certification    eWPTX Certification


🎯 Security Researcher | Speaker | Open Source Contributor

I'm a Product Security Engineer focused on securing the software supply chain. My passion lies in offensive security research, tool development, and sharing knowledge with the community.

  • 🔒 Creator of SCAGoat, a vulnerable-by-design application to benchmark SCA tools and simulate supply chain attacks.
  • 🧰 Regular secure coding trainer, conference reviewer, and CTF enthusiast.
  • 🔍 My research interests include OSS poisoning, model exposure abuse, malicious packages, and DevSecOps automation.

🛠️ Open Source Contributions

I believe in giving back to the community and actively contribute to key open source security projects:


🎤 Conference Talks & Arsenal

I have presented my research and tools at several top-tier security conferences, including:

Black Hat USA 2025 Black Hat Asia 2025 Black Hat Europe 2024 DEF CON 32 AppSec Village DC 2025


📊 GitHub Stats & Achievements

Streak Stats

Top Languages

GitHub Trophies


📌 Featured Project: SCAGoat

A deliberately insecure and compromised SCA testbed that simulates:

  • CVE exposure in Node.js and Spring Boot apps
  • Malicious/compromised packages
  • Reachability and fix validation workflows
    Ideal for evaluating SCA tools, container scanners, and CI/CD defenses.

Profile Views

💬 Let’s connect to talk about research, secure development, OSS risks, or collaborations!

Pinned Loading

  1. Damn-vulnerable-sca Damn-vulnerable-sca Public

    Damn Vulnerable SCA Application

    Java 43 61

  2. depcheck depcheck Public

    A CLI tool to identify SCA security vulnerabilities in packages and provide suggestions for upgrade versions, breaking changes, CVSS and advisories.

    Go 1

  3. flowlyt flowlyt Public

    Flowlyt is a security analyzer that scans GitHub Actions workflows to detect malicious patterns, misconfigurations, and secrets exposure, helping enforce secure CI/CD practices.

    Go 13 5

  4. scs-feed scs-feed Public

    Aggregates and updates supply chain security blog posts daily using GitHub Actions (runs every day at 00:00 UTC).

    JavaScript 1

  5. combat-sca combat-sca Public

    Python